Type Confusion Vulnerability in SuiteCRM by SalesAgility
CVE-2022-50590

8.8HIGH

Key Information:

Vendor

Suitecrm

Status
Vendor
CVE Published:
6 November 2025

What is CVE-2022-50590?

SuiteCRM versions before 7.12.6 are susceptible to a type confusion vulnerability due to improper handling of the ā€˜module’ parameter within the ā€˜deleteAttachment’ function. This flaw can be exploited by remote, unauthenticated attackers to manipulate database objects, effectively enabling them to alter critical information such as the administrator's email address. This vulnerability poses a significant risk to the integrity of the data within SuiteCRM and requires immediate attention and patching.

Affected Version(s)

SuiteCRM 0 < 7.12.6

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Exodus Intelligence
.
CVE-2022-50590 : Type Confusion Vulnerability in SuiteCRM by SalesAgility